Snarky Spider is a financially motivated eCrime threat actor associated with The Com and closely aligned with the broader Scattered Spider ecosystem. It is also tracked as O-UNC-025 and UNC6661. The group has been active since at least October 2025 and is known for rapid data-theft and extortion operations that rely heavily on social engineering rather than malware-heavy intrusion chains. Snarky Spider specializes in voice-phishing-led compromise of enterprise identity platforms and subsequent abuse of single sign-on access to move through SaaS environments. Its operators impersonate IT support or help desk personnel, direct victims to adversary-in-the-middle phishing pages themed as corporate single sign-on portals, and capture credentials, multifactor authentication codes, and session material. After gaining access to the victim identity provider, the group abuses trust relationships with connected cloud services to pivot across SaaS applications such as Microsoft 365, Google Workspace, SharePoint, HubSpot, and Salesforce. A defining characteristic of Snarky Spider is speed. Documented intrusions show the group moving from account takeover to data theft in less than five minutes, and in other cases beginning high-volume exfiltration within an hour of initial compromise. The actor operates almost exclusively inside trusted SaaS environments, reducing endpoint artifacts and complicating detection. Post-compromise activity includes registering attacker-controlled MFA devices for persistence, removing existing MFA devices, deleting security notifications, and creating inbox rules to suppress alerts related to unauthorized access or MFA changes. The group also scrapes internal directories to identify privileged users, conducts additional social engineering against higher-value accounts, and searches cloud repositories for sensitive business data for theft and extortion. Snarky Spider’s campaigns primarily target U.S.-based organizations across multiple sectors, including academic, aviation, retail, hospitality, automotive, financial services, legal, and technology organizations. Reported objectives center on rapid theft of high-value data followed by extortion, with some victim organizations also facing coercive follow-on tactics such as distributed denial-of-service attacks or employee harassment. The actor commonly uses residential proxy services and other legitimate infrastructure to obscure origin and blend with normal traffic. Overall, Snarky Spider represents a SaaS-centric, identity-focused extortion actor whose tradecraft emphasizes trusted access, minimal malware footprint, rapid execution, and aggressive monetization of stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses vishing for initial access, compromises single sign-on accounts, accesses cloud productivity environments, and rapidly moves from account takeover to data theft.
eCrime activity involving rapid progression from account takeover to data theft.
Uses vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts.
Uses vishing to gain access to victims' SSO-integrated SaaS applications through mobile-targeted phishing and MFA abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.